Legal
Cookie Policy
Cookie Policy
Reasoned Limited | Company No. 16859259 128 City Road, London EC1V 2NX, United Kingdom
team@reasonedfinance.com | https://reasonedfinance.com
Version 2.1 · Last updated: 21 September 2026
This policy replaces the September 2026 template. It is based on a code review plus a logged-out header scan of reasonedfinance.com and app.reasonedfinance.com on 21 September 2026. Logged-in cookies only appear after you sign in, so those rows come from the authentication code.
Read it alongside our Privacy Policy and Platform Terms of Service.
1. About this policy
This Cookie Policy explains how Reasoned Limited uses cookies and similar technologies on reasonedfinance.com, app.reasonedfinance.com and the product paths on those hosts (Learn, Compete, Get Hired).
We comply with PECR and UK GDPR. Anything that is not strictly necessary should wait for your consent. Where the live product still falls short of that (AdSense, consent storage), this policy says so.
2. What we found on a real scan
Logged out (21 September 2026): the HTML responses for reasonedfinance.com and app.reasonedfinance.com did not set cookies in the first response. Caddy is the public reverse proxy. No Meta, TikTok or LinkedIn pixels are loaded by our shared analytics script.
Logged in (from code): CentralHost sets first-party ch_access and ch_refresh when you sign in. Landing may set rt_ref if you arrive with a referral code.
Similar technologies (not HTTP cookies): local storage and a service worker are used. Those are listed in section 4.
Analytics: Google Analytics 4 and Microsoft Clarity load only after you press “Accept analytics” on the banner. They do not load if tools are not configured.
Advertising: Learn (and landing, via ca-pub-2865360651191765 in the landing HTML) can load Google AdSense when a publisher id is configured. That path is not currently tied to the analytics banner. Treat AdSense as advertising, not strictly necessary.
Email: we send mail from self-hosted BillionMail, not Brevo. Open/click tracking depends on the template; it is not a browser cookie on the Platform.
3. Cookies and similar technologies we use
3.1 Strictly necessary — no consent required
| Name | First or third party | Purpose | Duration |
|---|---|---|---|
ch_access | First-party (CentralHost, typically .reasonedfinance.com) | Signed-in session (JWT). HttpOnly | Access token TTL (minutes; configured as jwt_access_ttl) |
ch_refresh | First-party | Silent session refresh. HttpOnly | Refresh token TTL (configured as jwt_refresh_ttl) |
rt_ref | First-party (Landing) | Stores a referral code from the URL so sign-up can attribute it | 30 days |
reasoned_theme | First-party | Remembers light/dark theme if you set it via cookie | Persistent until changed |
| Stripe cookies | Third-party, Stripe domains | Checkout and fraud prevention | Only on payment pages; Stripe controls duration |
3.2 Consent record (first-party local storage)
| Name | Purpose | Duration |
|---|---|---|
rt_analytics_consent | Stores { analytics: true/false, updatedAt, version: 1 } after you use the banner | Until you clear site data |
rt_utm | First-party record of UTM / ref / r from the landing URL. Written without waiting for the banner. Not sent to Google until analytics is accepted | Until you clear site data |
This is not a server-side consent log, and we do not yet re-prompt every 6 months. Category-level choice (functional / advertising separately) is not built. The banner offers “Necessary only” and “Accept analytics”.
3.3 Analytics — only after “Accept analytics”
| Name | Provider | Purpose | Typical duration |
|---|---|---|---|
_ga, _ga_* | Google Analytics 4 | Distinguish visitors and measure pages | Up to 2 years (Google default) |
Clarity cookies (for example _clck, _clsk) | Microsoft Clarity | Session replay / heatmaps. We do not send your name or email to Clarity | Provider default |
GA4 is configured with anonymize_ip, and Google signals / ad personalization flags are off in our loader.
3.4 Advertising — AdSense (not on the current banner)
| Name | Provider | Purpose |
|---|---|---|
Google AdSense / DoubleClick cookies (for example IDE, others Google sets) | Display ads on Learn and, if the publisher meta tag is live, landing |
These are not strictly necessary. Until the banner includes an advertising category that gates AdSense, treat this as a known gap: if ads are configured they may set cookies without a separate advertising opt-in.
3.5 Functional local storage (not used for advertising)
| Name | Purpose |
|---|---|
reasoned-theme / rt-theme | Light/dark theme |
rt-edu-referral-code, rt_pending_ref | Referral code held across the sign-up modal |
PWA keys in reasoned-pwa.js | Install / last-prompt timestamps |
3.6 Service worker cache
The installable PWA caches shell assets so pages load on a poor connection. That cache is first-party. Clearing site data or unregistering the service worker removes it.
3.7 Categories we do not use today
We do not load Meta, TikTok or LinkedIn advertising pixels. We do not use Brevo (or Brevo email cookies) on the Platform. We do not send WhatsApp or marketing SMS.
4. The banner and Cookie settings {#settings}
4.1 When analytics tools are configured and you have no stored choice, we show a banner: Necessary only and Accept analytics.
4.2 That is not yet equal-prominence “Accept all” / “Reject all” with a category picker. “Necessary only” is the reject path for analytics.
4.3 Non-essential analytics cookies are not set until you accept. AdSense is the exception noted above.
4.4 Open Cookie settings (also in the footer) to change your mind. That re-opens the same two choices.
4.5 Closing the tab without choosing leaves analytics off.
5. If you block cookies
Blocking ch_access / ch_refresh will sign you out and stop authenticated use. Refusing analytics does not block Learn, Compete or Get Hired.
Browser help:
- Chrome: https://support.google.com/chrome/answer/95647
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
- Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
6. Third-party services
- Stripe — payments. https://stripe.com/cookies
- Google — sign-in, Analytics, AdSense. https://policies.google.com/technologies/cookies
- Microsoft Clarity — https://privacy.microsoft.com/privacystatement
- TradeLocker — competition sim, if you open that environment
- Discord / Instagram / LinkedIn — only if you follow our social links
7. Changes
We will update this page when a new scan or a product change adds or removes a cookie. Version and date are at the top. Previous versions stay at /legal/cookies/v1 after a replacement is published.